Everything you'd want to know before you install.
A detailed look at how PrestaShop Malware Scanner 8 & 9: Anti-Skimming, Magecart Protection and File Integrity works, why we built it the way we did, and the thinking behind the features above.
Why a back office security module is not enough
Protecting the login page stops a bot from coming in through the admin. A skimmer usually arrives another way: a vulnerable module, a compromised FTP or hosting account, a value injected into the database. It changes nothing visible and only adds a few lines to the code served to customers. This module watches exactly that code: files, database, the HTML actually sent on payment pages and what the customer's browser does.
Two views of checkout
On the server, the module inspects the HTML PrestaShop produces on cart, order and payment module controllers, and keeps an inventory of every script, iframe and form target. On the client, a small sentinel loaded before any other script watches network requests and elements added to the page. Together they cover injections stored in the database as well as those that only activate in the browser. A threshold of distinct visitors filters noise from browser extensions; an attempt to send a card number is reported at the first occurrence.
Update without a hundred alerts
An integrity monitor that alerts on every module update ends up ignored. The “I am updating my shop” button opens a two-hour window during which files changed without suspicious code become the new reference. A file containing malicious code still triggers an alert. Outside these windows, one summary per scan replaces file-by-file alerts, except for high-risk files which trigger an immediate alert.
The core compared with the official source
The reference recorded at installation takes the shop as it is. If it was already infected, the infection becomes the norm. The core check works around this: the module fetches the official source of your PrestaShop version and compares more than 5,000 files, ignoring line endings and the settings rewritten by the release build and debug mode. Each difference can be compared with the original and restored, with the modified version kept as evidence.
Evidence for your bank
Since March 2025, PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 call for a justified inventory of payment page scripts and detection of their changes. For each authorized script, the module records who authorized it, when and why, monitors third-party script content and security headers, and produces a printable report with the last 90 days of history. It supports the assessment; your acquirer or assessor remains the reference.
There are no reviews yet.